Is BingX Safe in 2026? Security, Licences and the 2024 Hack
Is BingX safe in 2026? Proof of Reserves, AUSTRAC and Lithuanian registrations, no MiCA, the $43M+ September 2024 hot-wallet hack and securing your account.
"Is BingX safe?" is really three questions. Is the company real and answerable to anyone? Has it lost customer money before, and what happened when it did? And what can you do to stop your own account being the weak point? This guide answers all three with the facts as they stand in 2026, including the September 2024 hot-wallet hack, and ends with a blunt risk assessment rather than a score out of ten.
The short version
BingX is a legitimate, operating exchange founded in 2018 that claims 40 million+ registered users, publishes Proof of Reserves, holds registrations in Australia and Lithuania, and suffered one significant hack, in September 2024, after which it covered user losses from its own funds. It is not licensed under MiCA in the EU and does not serve the USA, UK, Canada or several other large markets. That combination makes it a reasonable place to trade with money you can afford to leave on a centralized exchange, and a poor place to store a life's savings. The rest of this article is the evidence behind that sentence.
Regulatory status: registered, not fully licensed
It helps to be precise about what BingX holds, because marketing copy across the industry blurs "registered" and "licensed".
| Entity | Regulator | Status | What it actually means |
|---|---|---|---|
| BINGX GLOBAL PTY LTD | AUSTRAC (Australia) | Registered Digital Currency Exchange provider, reg. no. 644804571 | AML/CTF reporting obligations; not a prudential licence and not a guarantee of client funds |
| BINGX EU UAB | FCIS (Lithuania) | Registered Virtual Asset Service Provider | AML registration under Lithuanian law; not MiCA authorisation |
| EU-wide | MiCA | Not authorised as of mid-2026 | Cannot passport crypto-asset services across the EU under the MiCA regime |
| USA | FinCEN / state regulators | Not registered; US users excluded | No US legal protection whatsoever |
| UK | FCA | Not registered; UK users excluded | Cannot legally market to UK consumers |
AUSTRAC registration is real and verifiable on the regulator's public register, and it puts BingX under Australian anti-money-laundering supervision. The Lithuanian VASP registration is similar in scope. Neither is the kind of licence that comes with segregated client-money rules, capital requirements or a compensation scheme. Compare that to exchanges that have obtained MiCA authorisation for the EU market or a state-by-state US presence: those carry heavier obligations, and BingX has not taken them on.
The practical reading: BingX is not a shadow operation, but the regulatory backstop if something goes wrong is thin, and if you are in the EU you are dealing with a registered rather than MiCA-authorised provider.
Proof of Reserves
Since late 2022, when FTX's collapse made the question urgent, BingX has published Merkle-tree Proof of Reserves reports. The reports list the exchange's wallet holdings against customer liabilities for major assets (BTC, ETH, USDT and others) and report reserve ratios above 100%. You can verify that your own account balance was included in the snapshot by checking your Merkle leaf from the account page.
What this proves: at the snapshot moment, BingX controlled at least as many coins as customers were owed for the covered assets.
What it does not prove: anything about liabilities not on the list, off-chain borrowing, or the state of the balance sheet between snapshots. Proof of Reserves without a proof of liabilities audited by an independent firm is a partial picture. It is still far better than the nothing most exchanges offered before 2022, and BingX has been consistent in publishing it.
The September 2024 hot-wallet hack
This is the incident most people are asking about, and it is worth stating accurately because a lot of what circulates is wrong in one direction or the other.
What happened. On 20 September 2024, attackers gained access to BingX hot wallets on several chains and moved funds out in at least two waves several hours apart. Blockchain security firm PeckShield tracked roughly 26 million USD in the first wave and a further 16 million in the second, for a total near 43 million USD; other analysts who included more chains and later transfers put the figure at 44 to 52 million USD. The stolen assets, which included ETH, BNB, USDT and hundreds of smaller tokens, were swapped into ETH and BNB through decentralized exchanges, which is the pattern associated with state-linked hacking groups, though no attribution was officially confirmed.
How BingX responded. The exchange initially announced "wallet maintenance" and suspended deposits and withdrawals, then confirmed the breach within hours. Its Chief Product Officer described the loss as minor relative to total assets, said the overwhelming majority of funds were in cold storage and unaffected, and stated that BingX would cover all user losses from its own capital. Trading continued throughout. Withdrawals were restored in stages over roughly the following day after the wallet infrastructure was rebuilt.
What it means for users. No customer lost funds as a result of the hack; the hit was absorbed by the company. That is the most important fact, and it is a meaningfully better outcome than at exchanges that have socialized losses or gone under. The second most important fact is that the hack happened at all: hot-wallet key compromise is the most common exchange failure mode, and it demonstrated that a determined attacker could get at BingX's operational wallets. BingX says it has since overhauled its wallet architecture. There is no public independent audit of those changes to point to.
How to weigh it. An exchange that has been hacked and made customers whole has shown two things: that it had enough capital to eat a 43 million-plus loss, and that its management chose to. An exchange that has never been hacked has shown only that it has not been hacked yet. Neither is a guarantee about the future. The sensible response is not to avoid BingX because of 2024, but to treat every centralized exchange as a hot-wallet risk and size your on-exchange balance accordingly.
Other history and incidents
Beyond the 2024 hack, BingX's record is unremarkable in the way you would want. There are the usual complaints found for every exchange: KYC reviews taking longer than promised, withdrawal holds during risk checks, promotional bonuses with conditions people did not read. The bonus point is worth making explicit: the "5,685+ USDT welcome gift" is a set of tiered rewards (30 USDT max for registration, 500 max for deposit, 500 max for trading, plus further task tiers), conditional on KYC, a deposit of at least 200 USDT and trading-volume tasks, and mostly paid as futures trial funds rather than cash. That is not a scam, but it is a source of many "BingX stole my bonus" reviews from people who expected withdrawable money. The welcome bonus guide explains the actual conditions.
There has been no evidence of BingX halting withdrawals for solvency reasons, no regulatory enforcement action of note, and no leadership exodus. It is a mid-sized exchange that has run for eight years, which in this industry is itself a data point.
Account security tools you should actually turn on
The exchange's infrastructure is one attack surface. Your account is the other, and in practice most individual losses on any exchange come from phishing and credential theft rather than from the platform being breached. BingX gives you the standard toolkit; use all of it.
- Authenticator-app 2FA. Under Security, bind Google Authenticator or an equivalent. Avoid SMS 2FA: SIM-swap attacks defeat it, and phone numbers get recycled.
- Anti-phishing code. Set a word or phrase that BingX includes in every genuine email. Any email claiming to be from BingX without your code is fake, however good it looks.
- Withdrawal address whitelist. Enable it and add the addresses you actually use. New addresses are subject to a waiting period, which means a stolen session cannot instantly send funds somewhere new.
- Device management. Review the authorized-devices list occasionally and remove anything you do not recognize.
- Withdrawal password / passkey. Where available, add a second factor specifically for withdrawals, separate from login.
- Login alerts. Keep email and push notifications for new-device logins switched on.
Also, if you have not done so, complete KYC verification. It is not a security feature in itself, but an unverified account is harder to recover if you lose access, and it has low withdrawal limits.
Fake sites, fake apps and fake support
Because BingX runs a large referral and copy-trading ecosystem, it attracts a lot of impersonation. The common patterns:
- Look-alike domains promoted through search ads and Telegram: "bingx-login", "bingx.pro-app", a country-code variant. They harvest credentials and 2FA codes in real time. Type
bingx.comyourself, bookmark it, and never log in from a link. - Fake APKs on mirror sites. The genuine Android package is
pro.bingbon.apppublished by BINGX GROUP LIMITED; anything else is not it. The app download guide explains how to verify each platform. - "Support" in DMs. BingX staff do not initiate contact in Telegram, WhatsApp or X DMs and never ask for your password, 2FA code or a "verification deposit".
- Copy-trading signal groups claiming a BingX partnership and asking you to deposit through their link. The referral programme is real, but no legitimate partner needs you to send funds to them.
- Withdrawal "unlock fee" scams. An account that supposedly needs a payment to release funds is a fake account on a fake site. The real platform never charges to unlock a withdrawal.
If in doubt, the one thing that cannot be faked is the anti-phishing code in genuine emails, and the one place that cannot be spoofed is the address bar showing bingx.com with a valid certificate.
Restricted regions: who cannot use BingX
BingX's own disclaimer, as checked in July 2026, excludes residents of: the United States (including territories), United Kingdom, Canada, Singapore, Netherlands, Hong Kong SAR, Macau SAR, mainland China, Cambodia, Laos, Panama, Iran, North Korea, Cuba, Afghanistan, Myanmar, Somalia, Burundi, Central African Republic, DR Congo, Crimea, Donetsk and Luhansk.
This is a safety matter, not just a formality. An account opened from a restricted country using a VPN sits outside the terms of service; it can be frozen when KYC reveals the address, which usually happens exactly when there is a balance to lose. If you are in one of these places, use a platform licensed to serve you.
Honest risk assessment
Put the pieces together and this is a fair summary.
| Factor | Assessment |
|---|---|
| Legitimacy | Real company, 8-year track record, verifiable registrations. Not a scam. |
| Regulatory protection | Weak. AML registrations only; no MiCA, no US or UK licence, no deposit-protection scheme. |
| Reserves transparency | Good relative to peers; Merkle PoR published, but no audited proof of liabilities. |
| Security history | One major hot-wallet hack (2024, ~43–52M USD). Users fully compensated. Infrastructure since reworked, unaudited publicly. |
| Account tooling | Complete: app 2FA, anti-phishing code, whitelist, device management. |
| Impersonation risk | High, because of the referral and copy-trading ecosystem. Mitigated by the tooling above. |
| Regional exposure | Excluded in most large Western markets; do not circumvent. |
What that translates to in practice:
- Trading on BingX with a working balance is a reasonable risk for someone in a supported country who has locked down their account.
- Long-term storage on BingX is not sensible, any more than on any centralized exchange. Withdraw what you are not trading; the withdrawal guide covers fees and whitelisting.
- If regulatory protection is your priority, a MiCA-authorised or locally licensed exchange is a better fit even at slightly higher fees. Our comparisons with Bybit and Binance look at exactly that trade-off.
- Bonus offers and copy-trading returns are conditional and variable respectively; nothing on the platform is a guaranteed return.
If, after all that, you decide BingX fits your use case, create a BingX account with code PENDING for a permanent 20% rebate on trading fees; the registration guide shows the exact screens. For the broader picture of how the exchange performs day to day, the full BingX review on PerpCompass covers fees, products and support.
Frequently asked questions
Has BingX ever been hacked?
Yes. On 20 September 2024 attackers drained BingX hot wallets across several chains. On-chain trackers put the loss at roughly 43 to 52 million USD. BingX said cold storage was unaffected, paused withdrawals for about a day, and covered user losses from its own funds.
Is BingX regulated?
It holds registrations rather than full licences: BINGX GLOBAL PTY LTD is registered with AUSTRAC in Australia as a digital currency exchange provider, and BINGX EU UAB is registered with Lithuania's FCIS as a VASP. It is not MiCA-authorised as of mid-2026.
Does BingX publish Proof of Reserves?
Yes. BingX publishes Merkle-tree Proof of Reserves reports showing reserve ratios above 100% for major assets, and lets you verify your own balance is included. It is a reserve snapshot, not an audit of liabilities.
Can US, UK or Canadian residents use BingX?
No. The USA, UK, Canada, Singapore, Netherlands, Hong Kong, Macau and mainland China are among the jurisdictions BingX excludes in its terms. Accounts opened from those regions risk being frozen at KYC.
How do I protect my BingX account?
Use an authenticator app for 2FA rather than SMS, set an anti-phishing code, enable withdrawal address whitelisting, install the app only from bingx.com or the official stores, and keep most of your holdings off the exchange.
Is BingX safer than Binance or Bybit?
Larger exchanges have bigger insurance funds and, in some regions, fuller licences. BingX compensated users fully after its 2024 hack, which is a good sign, but it is a mid-tier exchange without MiCA or US licensing, and that should shape how much you keep there.